Aggregator
CVE-2026-24502 | Dell Command up to 4.6.x uncontrolled search path (dsa-2026-106)
CVE-2026-25590 | glpi-project glpi-inventory-plugin up to 1.6.5 cross site scripting (GHSA-54x7-6fhx-3wmw)
CVE-2026-21866 | langgenius dify up to 1.11.1 Mermaid Diagram cross site scripting (GHSA-qpv6-75c2-75h4)
CVE-2026-26266 | AliasVault up to 0.25.x Email cross site scripting (GHSA-f65p-p65r-g53q)
CVE-2026-26272 | sysadminsmedia homebox 0.20.1/0.24.0 SVG File Parser cross site scripting (GHSA-55fv-9q6q-vpcr)
CVE-2026-27905 | BentoML up to 1.4.35 Bento safe_extract_tarfile link following (GHSA-m6w7-qv66-g3mf / Nessus ID 300821)
CVE-2026-27622 | AcademySoftwareFoundation OpenEXR up to 3.2.5/3.3.7/3.4.5 EXR File Parser readPixels out-of-bounds write (GHSA-cr4v-6jm6-4963)
美国考虑采用乌克兰拦截无人机以应对伊朗
js逆向神器
js逆向神器
OpenAI Launches GPT-5.4 With Advanced Reasoning, Coding, and Computer-Use Capabilities
OpenAI on March 5, 2026, released GPT-5.4, its most capable and efficient frontier model to date, combining advanced reasoning, coding, and agentic workflows into a single unified system. The model is rolling out across ChatGPT (as GPT-5.4 Thinking), the API, and Codex, with a higher-performance GPT-5.4 Pro variant available for users requiring maximum compute on […]
The post OpenAI Launches GPT-5.4 With Advanced Reasoning, Coding, and Computer-Use Capabilities appeared first on Cyber Security News.
深度揭秘:OpenClaw Skill市场的火爆、风险与防御
每周勒索威胁摘要
Kill
You must login to view this content
JVN: Universal Boot Loader(U-Boot)におけるブートコードがコピーされる揮発性メモリに対するアクセス制御が不適切な脆弱性
甲骨文拟裁员数千人以缓解资金紧张问题
NanoFarfield: A Portable Far-Field Antenna Measurement Platform (Coming Soon to Crowdfunding)
PoC Exploit Released Cisco SD-WAN 0-Day Vulnerability Exploited in the Wild
A public proof-of-concept (PoC) exploit has been released for CVE-2026-20127, a maximum-severity zero-day vulnerability in Cisco Catalyst SD-WAN Controller and SD-WAN Manager that has been actively exploited in the wild since at least 2023. Cisco Talos is tracking the threat activity under the cluster UAT-8616, describing it as a “highly sophisticated cyber threat actor” targeting critical infrastructure […]
The post PoC Exploit Released Cisco SD-WAN 0-Day Vulnerability Exploited in the Wild appeared first on Cyber Security News.